same-clone-httpsphantom-com-0ov51pijrj2-latest[.]netlify[.]app
Análisis de phishing y seguridad de same-clone-httpsphantom-com-0ov51pijrj2-latest.netlify.app
“Phantom: The crypto wallet for everyone”
same-clone-httpsphantom-com-0ov51pijrj2-latest.netlify.app — Contenido no disponible (HTTP 404). Suplantación de marca: Phantom; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VT 15/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 0; URLScan no malicious verdict; GSB no flag; BL 0; CF Radar malicious; PD 95/100. Registrador: Netlify.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
PhishDestroy first observed same-clone-httpsphantom-com-0ov51pijrj2-latest.netlify.app on Sep 3, 2025. Positive findings were recorded by VirusTotal and Cloudflare Radar. Evidence score: 95/100.
VirusTotal recorded 15 detections among 95 engines: ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET, Forcepoint ThreatSeeker on Jul 18, 2026 at 18:45 UTC. Cloudflare Radar classified the domain as malicious; its source timestamp was not captured. The external blocklist snapshot contained no matches on Aug 7, 2026 at 14:20 UTC. URLQuery recorded no positive detection. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. URLScan completed without a malicious verdict (score 0) on Mar 5, 2026 at 22:29 UTC.
HTTP 404 was recorded on Aug 7, 2026 at 01:06 UTC; content was unavailable. Registration records list Netlify as the registrar. At collection time, the domain resolved to 18.208.88.157. Collected metadata identifies Phantom as the apparent target. Captured page title: “Phantom: The crypto wallet for everyone”. PhishDestroy classified the observed content as Crypto Scam. DOM analysis completed on Jul 29, 2026 at 04:18 UTC; stored DOM score 0/100. IoC extraction completed on Aug 3, 2026 at 04:01 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis25/07/2026
Analysis indicates the domain same-clone-httpsphantom-com-0ov51pijrj2-latest.netlify.app was an active brand impersonation threat targeting Phantom, a cryptocurrency wallet service. As of July 25, 2026, the domain has been taken offline and returns an HTTP 404 status. The page title, 'Phantom: The crypto wallet for everyone,' directly matches the branding of the legitimate Phantom service, confirming the intent to deceive users into believing the site was an official wallet portal. The domain was hosted on Netlify infrastructure and resolved to IP address 18.208.88.157, located in the United States under Amazon.com, Inc. (AS14618).
SSL certification was provided by DigiCert Inc, using a DigiCert Global G2 TLS RSA SHA256 2020 CA1 certificate, which does not inherently indicate malicious activity but is commonly observed in phishing infrastructure to lend a false sense of legitimacy. The domain appeared on one security blocklist, specifically PhishDestroy, and was flagged by 15 of 95 security vendors on VirusTotal, suggesting moderate detection coverage at the time of analysis. No nameserver data or additional hosting details were available. The scam type was classified as a crypto scam, though the exact mechanics—such as whether it functioned as a credential harvester, fake wallet distributor, or crypto drainer—remain unconfirmed due to the domain's current offline status.
Defenders should treat this domain as part of a broader pattern of Phantom impersonation campaigns, particularly those leveraging cloud hosting platforms like Netlify to rapidly deploy and rotate phishing pages. Organizations are advised to block the domain at the network level, monitor for related infrastructure using the unique seed '9c0ede,' and alert users to the prevalence of crypto wallet impersonation threats. Further investigation into the SSL certificate chain and hosting provider logs may reveal additional linked domains or attacker infrastructure.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 3 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100 % de confianzaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Acerca de este informe: same-clone-httpsphantom-com-0ov51pijrj2-latest.netlify.app
Este informe presenta la última evidencia almacenada disponible para PhishDestroy. Las marcas de tiempo de origen se muestran cuando están disponibles; La disponibilidad y los veredictos de los proveedores pueden cambiar después de la recolección.
El sitio capturado mostraba el título de la página “Phantom: The crypto wallet for everyone” y puede estar haciéndose pasar por Phantom.
A partir de 07/08/2026, same-clone-httpsphantom-com-0ov51pijrj2-latest.netlify.app tuvo detecciones de los motores de seguridad 15.
Si cree que esta lista es inexacta, presentar una apelación. Para conocer nuestra metodología, visita el Página de preguntas frecuentes.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.